Skip to content

Commit 1407520

Browse files
lukpuehJustinCapposjoshuagl
committed
Add details about ffwd attacker goals
Co-Authored-By: Justin Cappos <justincappos@gmail.com> Co-Authored-By: Joshua Lock <jlock@vmware.com>
1 parent 509fd21 commit 1407520

File tree

1 file changed

+5
-2
lines changed

1 file changed

+5
-2
lines changed

tuf-spec.md

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1114,12 +1114,15 @@ repo](https://github.com/theupdateframework/specification/issues).
11141114

11151115
* **1.9**. **Fast-forward attack recovery** A _fast-forward attack_ happens
11161116
when attackers arbitrarily increase the version numbers in any of the
1117-
timestamp, snapshot, targets, or delegated targets metadata. To recover from
1117+
timestamp, snapshot, targets, or delegated targets metadata. The attacker goal
1118+
is to cause clients to refuse to update the metadata later because the attacker's
1119+
listed metadata version number (possibly MAX_INT) is greater than the new valid
1120+
version. To recover from
11181121
fast-forward attacks after the repository has been compromised and recovered,
11191122
certain metadata files need to be deleted as specified in this section.
11201123
Please see [the Mercury
11211124
paper](https://ssl.engineering.nyu.edu/papers/kuppusamy-mercury-usenix-2017.pdf)
1122-
for more details.
1125+
for more details on fast-forward attacks.
11231126

11241127
* **1.9.1**. **Targets recovery** If a threshold of targets keys have been
11251128
removed in the new trusted root metadata compared to the previous trusted

0 commit comments

Comments
 (0)